
Introduction
The Digital Personal Data Protection Act, 2023 (DPDPA) was enacted on 11 August 2023 to provide a specific legal framework for the processing and protection of digital personal data in India.
The Act forms an important part of India’s developing privacy framework. Its constitutional background can be traced to the Supreme Court’s decision in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), where a nine-judge Bench unanimously recognised the right to privacy as a constitutionally protected fundamental right under Part III of the Constitution.
The DPDPA does not prohibit the use or processing of personal data altogether. Its purpose is to regulate the circumstances in which such processing may take place. The Act itself seeks to recognise both the right of individuals to protect their personal data and the need to process such data for lawful purposes.
Also Read – Children’s Freedom of Expression in the Digital Sphere
Scope and Applicability
Section 3 deals with the application of the Act. The DPDPA applies to digital personal data processed within India where the data is either collected in digital form or collected in non-digital form and subsequently digitised.
The Act also has an extra-territorial application. Processing undertaken outside India may come within its scope if it is connected with an activity relating to the offering of goods or services to Data Principals within India.
However, certain categories of processing are excluded. The Act does not apply to personal data processed by an individual for a personal or domestic purpose. It also excludes personal data made publicly available by the Data Principal herself or by another person who is legally required to make such information public.
This means that the DPDPA is concerned specifically with digital personal data. Personal data that continues to remain entirely in non-digital form does not fall within the scope contemplated under Section 3.
Also Read – Right to Be Forgotten in India: Law, Cases & DPDP Act
Important Terms under the DPDPA
A few terms used throughout the Act are important for understanding its framework.
- A Data Principal is the individual to whom the personal data relates. In the case of a child, the term includes the parent or lawful guardian. Where the individual is a person with disability, it may include the lawful guardian acting on their behalf.
- A Data Fiduciary is a person who, either alone or together with others, determines the purpose and means of processing personal data.
- A Data Processor, on the other hand, processes personal data on behalf of a Data Fiduciary.
The distinction is important because the principal responsibility for compliance remains with the Data Fiduciary even where processing has been entrusted to a Data Processor.
Also Read – Kharak Singh v. State of U.P. (1962): The Landmark Judgment That Laid the Foundation of the Right to Privacy
Consent and Certain Legitimate Uses
Section 4 permits personal data to be processed for a lawful purpose either on the basis of consent or for certain legitimate uses recognised under Section 7.
Consent under Section 6 must be free, specific, informed, unconditional and unambiguous, and must be indicated through a clear affirmative action. It should also be limited to personal data necessary for the specified purpose.
The Data Principal may withdraw consent at any time. The Act specifically requires that withdrawal should be as easy as the process through which consent was originally given.
Consent, however, is not the only basis for processing. Section 7 recognises certain legitimate uses, including specified situations involving voluntarily provided information, compliance with legal obligations, medical emergencies, employment-related purposes and certain functions performed by the State.
Rights of Data Principals and Obligations of Data Fiduciaries
The DPDPA provides Data Principals with several statutory rights. These include the right to obtain information about personal data being processed, seek correction, completion, updating or erasure of personal data, use the grievance redressal mechanism and nominate another individual to exercise their rights in the event of death or incapacity.
Sections 11 and 12 deal specifically with access, correction and erasure in relation to personal data for which the Data Principal has previously given consent, including the situation covered under Section 7(a).
Data Fiduciaries carry the main compliance responsibilities under the Act. Section 8 requires them to implement appropriate technical and organisational measures and take reasonable security safeguards to prevent personal data breaches.
If a personal data breach takes place, the Data Fiduciary is required to intimate the Data Protection Board of India and each affected Data Principal in the manner prescribed.
Personal data must also ordinarily be erased once consent is withdrawn or the specified purpose is no longer being served, unless its continued retention is necessary for compliance with another law. Data Fiduciaries are additionally required to establish an effective grievance redressal mechanism.
Protection of Children’s Personal Data
Section 9 contains additional safeguards relating to children. A child under the DPDPA is an individual who has not completed eighteen years of age.
Before processing a child’s personal data, the Data Fiduciary is generally required to obtain verifiable consent of the parent. The Act clarifies that the expression “parent” includes a lawful guardian wherever applicable.
The Act also restricts processing likely to have a detrimental effect on the well-being of a child. Tracking or behavioural monitoring of children and targeted advertising directed at children are prohibited, subject to exemptions permitted under the Act and the Rules.
Significant Data Fiduciaries
The Central Government may notify a Data Fiduciary or a class of Data Fiduciaries as Significant Data Fiduciaries (SDFs) after considering factors such as the volume and sensitivity of personal data processed, risk to the rights of Data Principals, sovereignty and integrity of India, electoral democracy, security of the State and public order.
SDFs are subject to additional obligations. These include appointing a Data Protection Officer based in India, appointing an independent data auditor, undertaking periodic Data Protection Impact Assessments and conducting periodic audits.
Data Protection Board and Penalties
The Act provides for the Data Protection Board of India to deal with specified breaches and proceedings under the DPDPA. The Board may conduct inquiries, issue directions and impose monetary penalties in accordance with the Act.
The Schedule prescribes different maximum penalties depending upon the nature of the breach. Failure to take reasonable security safeguards to prevent a personal data breach may attract a penalty of up to ₹250 crore.
Failure to comply with breach-notification requirements and breach of specified obligations relating to children may attract penalties of up to ₹200 crore.
Present Position
The DPDPA framework is being brought into operation in phases. The Central Government has also notified the Digital Personal Data Protection Rules, 2025.
Therefore, the applicability of a particular statutory obligation has to be examined with reference to the commencement of the relevant provision and Rule rather than proceeding on the assumption that every provision became operational at the same time.
Conclusion
Overall, the Digital Personal Data Protection Act, 2023 provides India with a dedicated framework for regulating digital personal data while recognising that data processing remains necessary for lawful purposes.
For individuals, the Act creates statutory rights relating to access, correction, erasure and grievance redressal. For organisations, compliance involves much more than simply maintaining a privacy policy. Consent practices, data retention, security safeguards, processor arrangements, breach response and grievance mechanisms all form part of the compliance framework.
The DPDPA therefore places data protection within the day-to-day compliance responsibilities of organisations dealing with digital personal data.
Join our WhatsApp Groups ( Click Here) and Telegram Channel ( Click Here) and get instant notifications.
